Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

TOJ RAJ PRADHAN

Bangalore

Summary

Results-driven Security Analyst experienced in enhancing organizational security and optimizing SOC operations. Achieved improvements in alert accuracy and threat mitigation through technical expertise and proactive strategies. Focused on leadership in escalations and operational continuity to ensure client satisfaction.

Overview

1
1
Certification
9
9
years of professional experience

Work History

Information Security Analyst

NTT DATA
Bangalore
12.2018 - 06.2024
  • Monitored and maintained security infrastructures for multiple clients, ensuring compliance with security policies and minimizing vulnerabilities.
  • Qradar SIEM: Created tuning correlation offense rules, and alerts to detect suspicious activities and potential security threats. Investigated security incidents, triaging alerts, and responding to incidents promptly to minimize impact and ensure business continuity. Integrated log sources in SIEM and removed decommissioned devices reported to SIEM. Conducted health checks and created reports in Qradar SIEM.
  • Azure Sentinel SIEM: Monitoring alerts and incidents generated by Sentinel, investigating security incidents using KQL queries search based on various tables, Defender for O365, Intra Id and Defender for Endpoint
  • Office 365 Defender: Monitoring for and detecting threats such as phishing attempts, malware, and suspicious activities within Office 365 applications (e.g., Exchange Online, SharePoint Online, Teams). Analyzed emails using explorer, email header, previewed the email or downloaded and performed Zero-Hour Auto-Purge (ZAP). Responsible for blocking email address, url and file hash in threat policy.
  • Microsoft Intra ID: Monitoring suspicious activities and detecting anomalies related to identities using Audit logs, Sign-in logs, risky users.
  • Zscalar Web Security: Configured and maintained policies that controlled user access to websites and applications based on organizational security requirements. This includes setting up URL filtering policies, providing insights, and application controls.
  • Proofpoint email security: investigating emails and taking necessary actions to contain and remediate threats. This includes analyzing email headers, content, and attachments to determine the nature and severity of the threat.
  • Elasticsearch: Using Elasticsearch aggregations, visualizations, and integrations with tools like Kibana to analyze and visualize data insights. Creating dashboards and reports to present findings and trends to stakeholders.
  • Duo Security and Hitachi ID management: Managing user accounts, roles, and permissions within the Duo Security platform and Hitachi ID management. This involves provisioning new users, assigning appropriate authentication policies, and ensuring secure user access across different applications and services.
  • Crowdstrike EDR: Responsible for monitoring endpoint activities and behaviors using Crowdstrike's EDR sensors. This includes tracking processes, file executions, network connections, registry changes, and scan on host in real time.
  • Supervised team shifts, ensuring operational efficiency and serving as primary point of contact for escalations to facilitate timely incident resolution.

Investigated and remediated true positive incidents, including email credential phishing, through detailed email analysis, execution of soft deletions, blocking of malicious URLs, and coordinated password resets to prevent account compromise and lateral movement.


  • Monitored network traffic for suspicious activities and potential threats.
  • Investigated security incidents and prepared detailed reports on findings.
  • Provided training sessions for L1s on best security practices and awareness.
  • Created detailed reports on security issues for senior management review.
  • Analyzed system logs and identified potential threats or risks.

Threat Analyst

Paladion Networks
Bangalore
09.2015 - 11.2018
  • Proficient in utilizing ArcSight SIEM and for security monitoring, threat detection and Logger
  • Designed and implemented custom ArcSight correlation rules for threat detection using Indicators of Compromise (IOCs) such as malicious IP addresses, domains, URLs, file hashes (MD5/SHA256), and email indicators.
  • Administered and maintained ArcSight ESM and Logger, managing active channels, dashboards, filters, reports, trends, and correlation rules to enhance security monitoring capabilities.
  • Supported SOC operations by developing and maintaining detection use cases for phishing, malware, brute-force attacks, privilege escalation, lateral movement, and policy violations.
  • Utilized ArcSight Logger for rapid log searching, event correlation, forensic investigations, and root-cause analysis across multiple security data sources.
  • Developed and managed Active Lists, Session Lists, and Watch Lists to support dynamic threat intelligence enrichment, IOC tracking, and automated alert generation.
  • Optimized correlation rules and use cases through fine-tuning of thresholds, conditions, and exception handling, reducing false positives and enhancing detection efficiency.
  • Created and scheduled daily, weekly, and monthly security reports for operational teams and management, delivering actionable insights into security incidents, threats, compliance metrics, and SOC performance.
  • Performed ArcSight content development, including creation of custom dashboards, data monitors, queries, reports, and real-time alerting mechanisms aligned with client security requirements.

Education

Bachelor of Engineering - Information science and Technology

Acharya Institute of Technology
Bangalore
01-2015

12th -

Gear PU College
Bangalore
01-2011

10th -

Vignan Steel City Public School (CBSE)
Visakapatnam
01-2009

Skills

Technical Skills:

SIEM management

Microsoft Sentinel

IBM QRadar

ArcSight ESM

ArcSight Logger

Logrhythm

Microsoft Security Stack

Microsoft Security XDR

Hitachi ID Management

Microsoft Defender for Office 365

Microsoft Defender for Endpoint

CrowdStrike Falcon

EDR solutions

Azure AD management

Microsoft Entra ID

Duo Security

Hitachi ID Management

Network & Web Security

Zscaler Internet Access (ZIA)

Proofpoint Email Threat Detection

Threat intelligence

IOC rule creation

URL Intelligence

Proxy Log Investigation

Threat intelligence

IOC rule creation

URL Intelligence

Certification

  • SC-200: Microsoft Security Operations Analyst, Microsoft, 01/01/23
  • Certified Ethical Hacker (CEH), EC Council, 01/01/18
  • ArcSight Certified Security Analyst HP0-A116, HP, 01/01/17
  • Solarwinds Certified Professional(SCP), #SCP5447

Timeline

Information Security Analyst

NTT DATA
12.2018 - 06.2024

Threat Analyst

Paladion Networks
09.2015 - 11.2018

Bachelor of Engineering - Information science and Technology

Acharya Institute of Technology

12th -

Gear PU College

10th -

Vignan Steel City Public School (CBSE)
TOJ RAJ PRADHAN